First published: Fri Nov 27 2020(Updated: )
An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, a different vulnerability than CVE-2019-16364.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
B&R Industrial Automation Aprol | <r4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19874 is a vulnerability in B&R Industrial Automation APROL before R4.2 V7.08 that allows injection and execution of arbitrary unintended commands on the web server.
CVE-2019-19874 has a severity rating of 9.8, which is considered critical.
B&R Industrial Automation APROL versions before R4.2 V7.08 are affected by CVE-2019-19874.
To fix CVE-2019-19874, users should update to version R4.2 V7.08 or a later version of B&R Industrial Automation APROL.
More information about CVE-2019-19874 can be found in the release notes provided by B&R Automation. (Link: https://www.br-automation.com/downloads_br_productcatalogue/BRP44400000000000000585952/APROL_R42_A1_ReleaseNotes_001.pdf)